Which path/filter/tier is right for me?
Start with the scenario that sounds most like your home, congregation, or household. We will surface the right setup URLs and download links instantly.
Christ-honoring DNS filtering
GraceDNS now lives entirely on Cloudflare Workers and serves every tier through DNS-over-HTTPS, so churches and families get private, faith-aligned filtering without maintaining hardware.
We never log DNS queries. Every tier is DNS-over-HTTPS only, so use a compatible client or helper app when your platform cannot speak HTTPS DNS on its own.
Congregations and ministries can roll out filters with simple, printable endpoints.
Parents set one tier on the router and every phone, TV, and tablet follows.
Believers on the go can point laptops and phones to GraceDNS in under a minute.
Why we serve
GraceDNS exists for pastors, parents, and everyday believers who just want wholesome internet without a rocket science manual. We quiet the noise so disciples can delight in Jesus online and offline.
Printable quick-starts help congregations and ministries deploy safe browsing without IT staff.
Three gentle tiers let parents choose the right balance of compatibility, conviction, and calm.
Simple instructions let any believer point a single phone or laptop to a Christ-honoring resolver.
Small schools and co-ops can match each room to a tier without extra software or licenses.
Plans for every household
Each tier builds on the last. Copy the DNS-over-HTTPS URL, the DNS-over-TLS hostname, or both—then drop them into the helper your platform uses, whether it is Private DNS, a router, DoH app, or profile.
Which path/filter/tier is right for me?
Start with the scenario that sounds most like your home, congregation, or household. We will surface the right setup URLs and download links instantly.
Gentle baseline fed by broad malware, phishing, and tracker intelligence with a light-touch policy.
Primary encrypted resolver for Eden—paste into any DoH-aware app, router, or profile.
Hostname for Android Private DNS or other DoT clients (port 853).
Builds on Eden with explicit content, gambling, proxy/VPN bypass points, and piracy domains. SafeSearch enforced.
HTTPS endpoint for Sinai—use wherever you need SafeSearch and stricter content rules.
Preferred Private DNS/DoT hostname when you want Sinai’s policy over TLS.
Everything in Sinai plus the most aggressive baseline and a dedicated sweep against full-spectrum advertising stacks.
Zion’s DoH endpoint for routers, helper daemons, or profiles; expect stricter ad blocking.
DoT hostname for Zion when Android Private DNS or TLS firewalls need the aggressive ad tier.
Stacks Zion with an extreme wildcard sweep that silences telemetry brokers, referral loops, and device analytics for locked-down installs.
Glory’s DoH endpoint for kiosks, chapels, or any lockdown profile.
DoT hostname for Glory when you need the wildcard sweep over TLS.
Setup in minutes
GraceDNS now speaks both DNS-over-HTTPS (DoH) and DNS-over-TLS (DoT). Copy whichever endpoint your device expects, then follow the playbook below to feed it into profiles, Private DNS, helper daemons, or routers.
Private DNS provider hostname.
sinai.gracedns.org) and save; Android now tunnels over DoT.Need a fallback for older devices? Apps like Intra or Nebulo still work by pasting the DoH URL instead.
Allow, open Settings → Profile Downloaded, and install the profile (passcode required).
https://sinai.gracedns.org/dns-query (or your chosen tier).Switch tiers any time—each hostname serves a fresh, signed .mobileconfig with the right headers, so no manual editing is required.
Install….
MDM suites can deploy the worker-hosted profile (e.g., https://sinai.gracedns.org/mobileconfig) org-wide with your preferred tier URL.
cloudflared proxy-dns --address 127.0.0.1 --port 53 --upstream https://sinai.gracedns.org/dns-query (swap tiers as needed).127.0.0.1 so every lookup rides the DoH tunnel.Any DoH stub resolver (AdGuard Home, Technitium, dnscrypt-proxy) works the same way.
Keep Eden as a fallback upstream in case you need quick allowlisting while you test Zion or Glory.
Need help? Email hello@gracedns.org for quick-start PDFs.
Glory is intentionally brutal—expect Microsoft 365, Meta, referral links, and app stores to break. Always keep Sinai or Zion handy for normal browsing.
Clear convictions
Rooted in Scripture
“Whatever you do, in word or deed, do it all in the name of the Lord Jesus.”
This single call from Colossians 3:17 steers individuals, families, and the whole Church as we filter the web.
Colossians 3:17 (NET)
Support the mission
We run GraceDNS because it serves churches, families, and students—not because it turns a profit. Gifts remain optional; they simply help us cover hosting, storage, and the time spent curating blocklists. If you want a gentle guideline, think $5/year per individual, $15/year per household, or $3/student/year for schools—give what fits your situation, or nothing at all.
GraceDNS isn’t a non-profit, so gifts aren’t tax-deductible and can’t be refunded. Stripe emails a receipt immediately, and the button stays here whenever you feel led to chip in.
Need a custom invoice? Email us.Need clarity?
Eden is a light-touch baseline anchored by malware, phishing, and tracker intelligence; Sinai adds explicit, gambling, bypass, and piracy protections plus SafeSearch; Zion layers on the aggressive ad-network sweep; Glory piles an ultra-aggressive wildcard tier that crushes telemetry/referral brokers and demands careful allowlisting.
Often. Zion already interrupts monetized CDNs, telemetry calls, and certain login helpers—Glory goes even further by silencing referral chains, Meta logins, WhatsApp avatars, Xbox achievements, and many SSO helpers. Microsoft 365's core domains are allowlisted, but plan to drop to Sinai or Eden when a service expects tracking to function.
Start with Sinai so explicit, gambling, bypass, and piracy hosts stay blocked; keep Eden for devices that need near-zero breakage, use Zion for chapels, kiosks, or study spaces that demand ad-free screens, and reserve Glory for locked-down installs with an admin ready to maintain allowlists.
Resolvers must see the domains you ask for, but we immediately drop them—no logs, analytics, or sales. We only accept encrypted DNS (DoH or DoT), so once your helper connects, every hop stays encrypted between you and our Cloudflare Workers.
Copy the DoH URL or DoT hostname for the new tier, paste it into your helper app, profile, Private DNS, or router, and save. Most DoH/DoT clients switch tiers instantly without a reboot.
No. GraceDNS is free for homes, ministries, and small schools. Businesses can reach out for a conversation.
Stewardship
Ole Brook Web Services, based in Mississippi, crafts dependable tools for churches and small businesses. GraceDNS is one of our gifts to the wider Body of Christ.
Visit olebrookwebservices.com